Privacy policy
What we collect, what is public, and how to reach the operator.
Version 2026-10-01.1 · USD pricing · UTC daily boards
Who handles your information
Operator: Raiverr Digital · Malaysia.
Email: support@topfrontlane.com.
Development preview: business identity and jurisdiction must be configured before live payments are enabled. Sandbox payments do not move real money.
This policy covers Frontlane, including public listings, Stripe payment references, operator access, and the private support form. Third-party destination websites have their own policies.
What is public
A listing’s URL, name, description, category, original submission date, eligible paid totals, paid confirmation history, rank, and aggregate click count are public. These fields may identify you if you submit a personal website or X profile. Do not include private contact details or sensitive information in listing text. Visitors can copy or share public information; the operator cannot control third-party copies.
Payments and private records
Stripe collects and processes payment details on its hosted Checkout. Card numbers and bank details are not sent to or stored by this application. The application stores an order reference, listing details, amount, chosen board and target, Checkout/session and payment references, status, policy version, timestamps, and refund/dispute adjustments. These are used to fulfill placements, reconcile outcomes, prevent duplicate charges, handle complaints, and maintain records.
The operator can access additional transaction information, such as billing details and receipts, in its Stripe account. Stripe processes data under its own terms and privacy policy.
Support, reports and operator access
The support form collects your reply email, request type, optional listing URL, message, reference, and open/closed status. It is private and available only through authenticated operator endpoints. We use it to answer questions, investigate reports, handle corrections/refunds/privacy requests, and follow up when needed. Replies are handled manually by the operator; submitting a form does not automatically send email.
Operator sessions store a random session identifier and expiry. Moderation audit records store the action, listing reference, and timestamp. We do not publish your support email or private message.
Cookies, local storage and IP addresses
The website stores a light/dark theme preference in local storage. Essential HttpOnly, SameSite operator and owner cookies keep authenticated users signed in for up to eight hours and is revoked on logout; HTTPS deployments use a Secure cookie. Browsing and free submission do not set a login cookie. Owners who sign in receive an essential owner session cookie.
IP addresses are used temporarily in memory for request limits and abuse prevention, with windows of up to one hour. They are not stored in listing or support records. The application does not include advertising trackers or third-party analytics. Fonts and branding assets are served locally. Hosting, proxy, Stripe, and email systems may keep their own security or operational logs.
Why data is used and who receives it
We use information to provide the requested directory and paid placement service, manage support, maintain security, prevent fraud, and meet legal or accounting obligations. Where data-protection law requires a legal basis, these purposes may rely on performance of the requested service, legitimate interests in a safe and functioning directory, or legal obligations, as applicable. A required acknowledgment of this notice is not consent to unrelated marketing.
The operator and necessary hosting, payment, backup, and email providers may access data for their services. Public listing fields are visible to everyone. The application does not sell support information, use it for advertising profiles, or send marketing campaigns. We may disclose relevant records when lawfully required or necessary to address fraud, disputes, or threats to safety.
Owner verification and traffic measurement
Optional owner verification stores a listing association, verification date and a hash of its private owner key. Pending DNS challenges expire after 24 hours. A verified-domain label means control of the hostname, not product quality, safety or an endorsement. Owner sessions expire after eight hours and are revoked on logout.
To estimate exposure and outbound clicks, the app computes a daily keyed hash from the request IP address and browser type. Raw IP addresses and browser strings are not saved in traffic records. These hashes are pseudonymous data, not guaranteed anonymous. Recognized bots and repeat observations in one UTC day are filtered; shared connections can be undercounted. Traffic records are retained for up to 30 UTC days. No cross-site advertising tracking is used, and we do not measure activity on destination websites.
Retention and backups
Listings remain while published; hiding removes public visibility but preserves the underlying record for review. Transaction and moderation records remain for operation, payment disputes, fraud prevention, and applicable accounting/legal requirements; removal is reviewed by the operator rather than automatically erasing valid transactions.
Open support requests remain until resolved. Closed support requests are automatically removed after 180 days, checked hourly while the server runs and on startup. Expired operator sessions are removed. New automatically dated database backups are verified and kept for 14 days; older manual or hosting-provider backups follow their own retention settings. a removal from the active database does not immediately erase old backups. The operator must manage backup retention and any mandatory transaction-record periods for its jurisdiction before live launch.
Your choices and requests
You can avoid submitting personal information, clear your theme preference through browser storage settings, and request access, correction, removal, or restriction by contact support. Choose Privacy request and identify the relevant URL or order reference. We may need proportionate verification to protect someone else’s information; do not send identity documents unless the operator specifically requests them through an appropriate channel.
Rights such as objection or portability, response deadlines, and the ability to complain to a supervisory authority depend on applicable law. The operator will assess your request under that law and explain any records it must retain. Public search results and third-party copies may take longer to update.
Security, location and children
The app restricts private records to the operator, verifies payment notifications, validates input, limits abusive requests, and uses security headers. No system can guarantee absolute security. Report a suspected issue privately through Contact and avoid accessing other people’s records.
Frontlane is hosted on HostArmada in London, United Kingdom; local development also runs on the operator’s PC. Hosting, Stripe and email providers may process data in other countries. Applicable transfer requirements must be assessed when choosing hosting and activating live service. The service does not knowingly request sensitive information or target children. Payments require legal capacity or an authorized adult; contact support if a child’s personal information has been submitted.
Updates and contact
Policy version: 2026-10-01.1. We update this page when data practices change. For questions or privacy requests, contact support. The operator’s identity and public contact details appear above.
Need help? Contact the operator ↗